Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Zoom Chrome Extension For Gov

pnlbnejodfpnapdpoiboebofddaejkbg
Risk Score
3.12
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Productivity
Installs 3,000
Rating
Last updated 2026-05-23 (1 months ago)
Manifest version MV3
CSP present ✅ yes
Developer support@zoom.us
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but scope_extension=false AND data_collection+third_party_sharing=true — policy admits sharing but does not scope to this extension.
  • install_url_hijack flag set true; onInstalled behaviour opens external URL (target null, but flag is authoritative).
  • Operator cluster has 1 sibling extension under same fingerprint; warrants cross-check.
  • CSP script-src allows remote *.google.com and *.zoomgov.com domains — remote script execution possible from those origins.
  • No ratings/reviews (0 rating, 0 count) limits social-proof signal; low install count for a gov-facing tool.

Evidence

  • privacy_policy_generic api Policy fetched, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy (v3.5 rule D).
  • install_url_hijack crx install_url_hijack=true; target null. Rubric: onInstalled opens 3rd-party URL +2.0 Webstore.
  • operator_cluster api sibling_count=1 (kgjfgplpablkjnlkjmjdecgdpfankdle); +2.5 Webstore per rubric.
  • csp_remote_script_src manifest script-src includes https://*.google.com https://*.zoomgov.com — allows remote script loads from those origins.
  • confirmed_owner_no_impersonation api brand_mention.confirmed_owner=true, is_impersonation=false; developer domain zoom.us resolves.
  • no_cve_findings crx cve_findings_raw empty; jquery 3.7.1 has no known CVEs.
  • code_clean crx code_findings_raw empty, obfuscation_score=0.0; no exfil or eval indicators.
  • recently_updated store months_since_update=1; Maintenance pillar = 0.0.

Permissions Breakdown

  • storage low Local key-value storage; no cross-site exposure.
  • unlimitedStorage low Removes storage quota; low direct risk without other broad permissions.
  • host: https://www.google.com/calendar/* medium Content-script / request access scoped to Google Calendar only.
  • host: https://calendar.google.com/calendar/* medium Content-script / request access scoped to Google Calendar only.
  • host: https://*.zoomgov.com/* medium Broad wildcard on gov Zoom subdomain; acceptable for stated function.

Pillar Scores

Permissions1.50
Reputation3.00
Network1.50
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Operator Siblings (1)

Other extensions sharing this developer's compound fingerprint:

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:05
Listing SHA 547ba45b0eaf…
Force block — not fired
Score recovered no
Elapsed 23.6s